Security researchers have captured 120,000 emails intended for Fortune 500 companies by exploiting a basic typo. The emails included trade secrets, business invoices, personal information about employees, network diagrams and passwords.
Researchers Peter Kim and Garrett Gee did this by buying 30 internet domains they thought people would send emails to by accident (a practice known as typosquatting).
The domain names they chose were all identical to subdomains used by Fortune 500 companies save for a missing dot.
Having purchased the domains they simply sat back and watched as users mistakenly sent them over 120,000 emails in six months.